CVE-2026-76679
Analyzed Analyzed - Analysis Complete

Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways

Vulnerability report for CVE-2026-76679, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-28

Assigner: Hewlett Packard Enterprise (HPE)

Description

Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-28
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
arubanetworks edgeconnect_sd-wan_orchestrator From 9.4.0 (inc) to 9.4.11 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator From 9.5.0 (inc) to 9.5.9 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator From 9.6.0 (inc) to 9.6.4 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator 9.7.0
hpe edgeconnect_operating_system From 9.4.0.0 (inc) to 9.4.9.0 (exc)
hpe edgeconnect_operating_system From 9.5.0.0 (inc) to 9.5.9.0 (exc)
hpe edgeconnect_operating_system From 9.6.0.0 (inc) to 9.6.4.0 (exc)
hpe edgeconnect_operating_system 9.7.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in HPE Networking EdgeConnect SD-WAN Gateways allows an unauthenticated attacker on the same network to perform denial-of-service attacks. Exploiting it could crash the system, requiring manual reboot to restore operations and disrupting network services.

Detection Guidance

This vulnerability involves denial-of-service attacks on HPE Networking EdgeConnect SD-WAN Gateways. Detection requires monitoring for system crashes or unresponsive devices. Check logs for unusual traffic patterns or repeated crashes. No specific commands are provided in the available context.

Impact Analysis

If exploited, this vulnerability could cause network outages by crashing your SD-WAN gateways. This would interrupt business operations, remote access, and critical communications until the system is manually rebooted.

Compliance Impact

This vulnerability could disrupt network operations by causing system crashes, potentially leading to unauthorized access or data breaches. Such disruptions may violate compliance requirements under GDPR or HIPAA, which mandate continuous availability and protection of sensitive data.

Mitigation Strategies

Apply security patches or firmware updates provided by HPE immediately to address the vulnerability. Isolate affected systems from the network if possible to prevent exploitation. Monitor network traffic for unusual activity that may indicate an attack.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76679. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart